PaperCut Zero-Day Patch Urged
PaperCut Software warns of exploited zero-day in NG/MF, releases emergency patch and IoCs.
26 results for “zero-day”
PaperCut Software warns of exploited zero-day in NG/MF, releases emergency patch and IoCs.
AI can find zero-days but still can't reliably write secure code, studies show.
New Lazarus campaign abuses Windows zero-day and fake job lures to breach defense firms, fooling Google's filters.
Ivanti releases updates for Endpoint Manager and Neurons for MDM addressing remotely exploitable vulnerabilities.
August's Patch Tuesday addresses 398 vulnerabilities, including an actively exploited zero-day, as AI-driven discovery swells update volumes.
Microsoft's August Patch Tuesday fixes 421 CVEs, including one exploited zero-day and two publicly disclosed flaws.
SAP's August 2026 patch batch addresses 28 flaws, including a 10/10 severity bug in Commerce Cloud that could allow attackers to bypass authentication and execute code.
A zero-day in Metabase exposed Framework customer names, emails, and addresses; payment data was safe.
Critical SQL injection flaw in Metabase allowed zero-day attacks; urgent patches released for self-hosted users.
A static credential vulnerability in Cisco Secure FMC Software is undergoing active exploitation in the wild, according to the company.
Researchers used AI agents to uncover remote code execution vulnerabilities in Redis, prompting seven urgent security releases.
A sophisticated threat actor utilized zero-day exploits to gain deep access to SonicWall VPN appliances before official patches existed.
A persistent security researcher has unveiled a local privilege escalation bug for Windows 11, raising questions about severity.
Researchers are moving beyond theoretical AI capabilities, building automated pipelines to find live vulnerabilities in software.
With a record-breaking July release, Microsoft faces mounting pressure as AI-driven discovery accelerates the vulnerability cycle.
Critical SSRF and code injection flaws in SMA1000 appliances are currently being exploited, prompting an urgent patching mandate.
Microsoft addresses a record-breaking 570 vulnerabilities in its July update, including three active zero-day exploits.
Microsoft has addressed the RoguePlanet vulnerability, ending a contentious saga with security researcher Nightmare Eclipse.
A critical high-risk vulnerability in Chrome’s Intents feature has been patched, marking the fifth exploited zero-day of the year.
Critical updates for iOS and macOS patch two actively exploited zero-day vulnerabilities affecting kernel and WebKit components.
A recently disclosed proof-of-concept exploit targeting Windows Defender brings renewed focus to the fragility of enterprise security software.
A fix for a critical zero-day vulnerability inadvertently introduces a secondary risk that could lead to complete hard drive exhaustion.
The exploitation of critical Joomla extensions highlights a broader trend of automated campaigns targeting vulnerable CMS plugins globally.
A look inside IRIS C2, a mysterious cyber firm offering multimillion-dollar bounties but secretly run by notorious political schemers.
As Progress Software forces ShareFile servers offline, a sudden threat exposes the vulnerabilities inherent in hybrid storage systems.
Progress Software orders customers to sever internet access to their storage controllers, signaling an escalating, unpatched security risk.